Passive DNS and WHOIS in CTI: What Can You Safely Conclude?
Use historical DNS and registration data for discovery and corroboration without mistaking co-location, privacy services, or stale records for shared control.
Passive DNS and registration history are powerful for finding earlier infrastructure, narrowing time windows, and corroborating relationships. Their records are observations shaped by sensor coverage and administrative processes—not direct proof of who controlled a resource.
Before querying, name the decision: discover related domains, validate an incident timestamp, assess infrastructure reuse, or determine whether an artifact is safe to operationalize. The claim you may responsibly make depends on source coverage and supporting evidence.
Preserve What the Record Actually Says
Capture provider, query time, first and last observation, record type, value, count if meaningful, and the provider’s definition. Different datasets may report different windows because they observe different traffic.
For registration data, preserve retrieval date, registrar, creation and update dates, status, nameservers, registrant fields where lawful, and privacy or redaction state. A record may describe an administrative account rather than the operational user.
Judge Specificity and Temporal Overlap
A domain on a dedicated address during the incident window is more specific than a domain that once touched a large CDN. Reused rare certificates, coordinated registrations, distinctive nameserver changes, matching content, and narrow timing can strengthen a relationship.
Shared registrars, privacy services, cloud ranges, or common nameservers are weak. Treat each as a lead, then seek an independent feature. Check reassignment before applying an old relationship to current ownership.
Separate Discovery From Enforcement
Use low-confidence associations for analyst pivots, moderate associations for monitoring or enrichment, and validated current malicious use for blocking or alerting. Label the artifact’s role, time window, confidence, and legitimate-use risk.
Re-query before action and document the decision. For a broader pivot method, use Threat Infrastructure Analysis.
Write Bounded Conclusions
Prefer: “Provider X observed domain A resolving to address B between these dates; the address hosted many unrelated domains, so this is a weak relationship.” Avoid: “Actor X owned address B.”
Bounded wording preserves the value of historical data while preventing a discovery lead from becoming false attribution or collateral blocking. State what further evidence would strengthen or disprove the link.
Frequently asked questions
What does passive DNS show?
It shows that a provider observed a domain-to-record relationship at a reported time; it does not necessarily show ownership or exclusive control.
Does no passive DNS result mean a domain never resolved?
No. Coverage varies by provider, region, record type, and time. Absence is usually a collection gap rather than proof.
Is privacy-protected WHOIS suspicious?
No. Privacy protection is widely legitimate and has little evidentiary value without other distinctive features.
Does the same registrant prove common control?
Not by itself. Records can be stale, false, proxied, transferred, or reused; corroborate with timing, infrastructure, content, and behavior.
Can historical data justify a current block?
Historical relationships can support investigation, but current enforcement requires fresh validation and consideration of reassignment and legitimate shared use.